feat(cli): land journal binary surface (M2) master
M1 lit up both `sol` and `journal` entrypoints with a surface-filtered registry. M2 closes the migration gap: `sol --help` is now grouped into five owner-facing sections (Conversation / Your journal / See & diagnose / Tools / Journal service), every internal service-tagged invocation migrates to `journal <cmd>`, and the source-checkout wrapper installs both `~/.local/bin/sol` and `~/.local/bin/journal` atomically — either both reflect the new state or both reflect the old. Existing `sol <service-cmd>` calls keep working bit-for-bit (no deprecation warnings; that's M3). Notable shape: - `print_help()` derives the Journal service group from the registry so the partition can't drift; the AC1 drift test asserts every COMMANDS key lands in exactly one group. - `install_guard.render_wrapper()` parameterizes on `binary`, and `install_wrappers()` writes/rewrites both targets under one `wrapper_lock()` with snapshot-restore rollback on mid-failure. - `service.py` switches the launchd/systemd unit body to `journal supervisor`; `remove_stale_plists` accepts both `/sol` and `/journal` endings so already-installed units are not stale-removed. - Three `prog=` strings dropped (heartbeat, setup, config) — argparse now inherits the runtime-modified `sys.argv[0]`, so usage lines render the right binary name. Lode: solstone-journal-cli-m2 (hopper iuq7x7nk). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>